CVE-2026-90809: HKUDS nanobot ExecTool shell.py ExecTool._spawn argument injection
A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool.guardcommand/ExecTool.spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argument injection. It is possible to launch the attack remotely. The name of the patch is af582246f141311d574551b7571a517bcc3df750. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HKUDS nanobotto a version that resolves this vulnerability.Patch af582246f141311d574551b7571a517bcc3df750
Event History
Frequently Asked Questions
Which versions are affected?
HKUDS nanobot versions up to and including 0.2.1 are affected.
Can this be exploited remotely without authentication or user interaction?
Yes. The supplied severity vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the impact of successful exploitation?
The provided vector rates confidentiality, integrity, and availability impact as low. The vulnerability allows argument injection in ExecTool's command-guarding and process-spawning functionality.
What remediation is available?
Apply the patch identified as af582246f141311d574551b7571a517bcc3df750.